A authorization bypass through user-controlled key in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.8 may allow an authenticated attacker to view unauthorized device information via key modification in API requests.
References
Link | Resource |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-24-274 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
22 Jul 2025, 21:24
Type | Values Removed | Values Added |
---|---|---|
References | () https://fortiguard.fortinet.com/psirt/FG-IR-24-274 - Vendor Advisory | |
CPE | cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiportal:7.4.0:*:*:*:*:*:*:* |
|
First Time |
Fortinet fortiportal
Fortinet |
12 Jun 2025, 16:06
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
10 Jun 2025, 17:19
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-10 17:19
Updated : 2025-07-22 21:24
NVD link : CVE-2024-45329
Mitre link : CVE-2024-45329
CVE.ORG link : CVE-2024-45329
JSON object : View
Products Affected
fortinet
- fortiportal
CWE
CWE-639
Authorization Bypass Through User-Controlled Key